CodeQL
FreeNot checkedBridges to the CodeQL static analysis engine for identifying security vulnerabilities and quality issues in codebases through structured query evaluation and re
About
Bridges to the CodeQL static analysis engine for identifying security vulnerabilities and quality issues in codebases through structured query evaluation and result interpretation.
README
This project runs a Model Context Protocol (MCP) server that wraps the CodeQL query server. It enables tools like Cursor or AI agents to interact with CodeQL through structured commands and doc search.
Features
- ✅ Register CodeQL databases
- ✅ Run full queries or quick-evaluate a symbol
- ✅ Decode
.bqrsfiles into JSON - ✅ Locate predicate/class symbol positions
File Structure
| File | Purpose |
|---|---|
server.py |
Main FastMCP server exposing CodeQL tools |
codeqlclient.py |
CodeQLQueryServer implementation (JSON-RPC handler) |
Requirements
Install with uv:
uv pip install -r requirements.txt
or with pip:
pip install fastmcp httpx
Running the MCP Server
uv run mcp run server.py -t sse
- Starts the server at http://localhost:8000/sse
- Required for Cursor or AI agent use
Cursor Config
Make sure your .cusor/config.json contains:
{
"mcpServers": {
"CodeQL": {
"url": "http://localhost:8000/sse"
}
}
}
Notes
- Tools like Cursor will invoke these commands directly via natural language.
- You must have a codeql binary in your $PATH, or hardcode its path in codeqlclient.py.
- You should probably specify query locations, query write locations and database paths in your prompts.
Installing CodeQL
This server has no published package — it is built from source. Open the repository and follow its README.
▸ github.com/jordyzomer/codeql-mcpFAQ
Is CodeQL MCP free?
Yes, CodeQL MCP is free — one-click install via Unyly at no cost.
Does CodeQL need an API key?
No, CodeQL runs without API keys or environment variables.
Is CodeQL hosted or self-hosted?
Self-hosted: the server runs locally on your machine via the install command above.
How do I install CodeQL in Claude Desktop, Claude Code or Cursor?
Open CodeQL on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.
Related MCPs
GitHub
PRs, issues, code search, CI status
by GitHubFilesystem
Secure file operations with configurable access controls.
Memory
Knowledge graph-based persistent memory system.
Template MCP Server
A CLI tool to create a new Model Context Protocol server project with TypeScript support, dual transport options, and an extensible structure
by mcpdotdirectCompare CodeQL with
Not sure what to pick?
Find your stack in 60 seconds
Author?
Embed badge for your README
Browse similar
All development MCPs
